You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We've released a new major version of Azure Active Directory Connect. This version contains several updates of foundational components to the latest versions and is recommended for all customers using Azure AD Connect. [Learn more](../hybrid/whatis-azure-ad-connect-v2.md).
42
+
43
+
---
44
+
45
+
### Public Preview - Azure AD single Sign on and device-based Conditional Access support in Firefox on Windows 10
46
+
47
+
**Type:** New feature
48
+
**Service category:** Authentications (Logins)
49
+
**Product capability:** SSO
50
+
51
+
52
+
We now support native single sign-on (SSO) support and device-based Conditional Access to the Firefox browser on Windows 10 and Windows Server 2019. Support is available in Firefox version 91. [Learn more](../conditional-access/require-managed-devices.md#prerequisites).
53
+
54
+
---
55
+
56
+
### Public preview - beta MS Graph APIs for Azure AD access reviews returns list of contacted reviewer names
57
+
58
+
**Type:** New feature
59
+
**Service category:** Access Reviews
60
+
**Product capability:** Identity Governance
61
+
62
+
63
+
We've released beta MS Graph API for Azure AD access reviews. The API has methods to return a list of contacted reviewer names in addition to the reviewer type. [Learn more](/graph/api/resources/accessreviewinstance).
64
+
65
+
---
66
+
67
+
### General Availability - "Register or join devices" user action in Conditional Access
The "Register or join devices" user action is generally available in Conditional access. This user action allows you to control multi-factor authentication policies for Azure Active Directory (AD) device registration. Currently, this user action only allows you to enable multi-factor authentication as a control when users register or join devices to Azure AD. Other controls that are dependent on or not applicable to Azure AD device registration continue to be disabled with this user action. [Learn more](../conditional-access/concept-conditional-access-cloud-apps.md#user-actions).
75
+
76
+
---
77
+
78
+
### General Availability - customers can scope reviews of privileged roles to eligible or permanent assignments
79
+
80
+
**Type:** New feature
81
+
**Service category:** Access Reviews
82
+
**Product capability:** Identity Governance
83
+
84
+
Administrators can now create access reviews of only permanent or eligible assignments to privileged Azure AD or Azure resource roles. [Learn more](../privileged-identity-management/pim-create-azure-ad-roles-and-resource-roles-review.md).
85
+
86
+
---
87
+
88
+
### General availability - assign roles to Azure Active Directory (AD) groups
89
+
90
+
**Type:** New feature
91
+
**Service category:** RBAC
92
+
**Product capability:** Access Control
93
+
94
+
95
+
Assigning roles to Azure AD groups is now generally available. This feature can simplify the management of role assignments in Azure AD for Global Administrators and Privileged Role Administrators. [Learn more](../roles/groups-concept.md).
96
+
97
+
---
98
+
99
+
### New Federated Apps available in Azure AD Application gallery - Aug 2021
100
+
101
+
**Type:** New feature
102
+
**Service category:** Enterprise Apps
103
+
**Product capability:** 3rd Party Integration
104
+
105
+
In August 2021, we have added following 46 new applications in our App gallery with Federation support:
For more information about how to better secure your organization by using automated user account provisioning, see Automate user provisioning to SaaS applications with Azure AD.
To help administrators understand that their users are blocked for multi-factor authentication as a result of fraud report, we’ve added a new audit event. This audit event is tracked when the user reports fraud. The audit log is available in addition to the existing information in the sign-in logs about fraud report. To learn how to get the audit report, see [multi-factor authentication Fraud alert](../authentication/howto-mfa-mfasettings.md#fraud-alert).
To improve the quality of low risk alerts that Identity Protection issues, we've modified the algorithm to issue fewer low risk Risky Sign-Ins. Organizations may see a significant reduction in low risk sign-in in their environment. [Learn more](../identity-protection/concept-identity-protection-risks.md).
Identity Protection now emits risky sign-ins on non-interactive sign-ins. Admins can find these risky sign-ins using the **sign-in type** filter in the risky sign-ins report. [Learn more](../identity-protection/howto-identity-protection-investigate-risk.md).
160
+
161
+
---
162
+
163
+
### Change from User Administrator to Identity Governance Administrator in Entitlement Management
164
+
165
+
**Type:** Changed feature
166
+
**Service category:** Roles
167
+
**Product capability:** Identity Governance
168
+
169
+
The permissions assignments to manage access packages and other resources in Entitlement Management are moving from the User Administrator role to the Identity Governance administrator role.
170
+
171
+
Users that have been assigned the User administrator role can longer create catalogs or manage access packages in a catalog they don't own. If users in your organization have been assigned the User administrator role to configure catalogs, access packages, or policies in entitlement management, they will need a new assignment. You should instead assign these users the Identity Governance administrator role. [Learn more](../governance/entitlement-management-delegate.md)
172
+
173
+
---
174
+
175
+
### Windows Azure Active Directory connector is deprecated
The Windows Azure AD Connector for FIM is at feature freeze and deprecated. The solution of using FIM and the Azure AD Connector has been replaced. Existing deployments should migrate to [Azure AD Connect](../hybrid/whatis-hybrid-identity.md), Azure AD Connect Sync, or the [Microsoft Graph Connector](/microsoft-identity-manager/microsoft-identity-manager-2016-connector-graph), as the internal interfaces used by the Azure AD Connector for FIM are being removed from Azure AD. [Learn more](/microsoft-identity-manager/microsoft-identity-manager-2016-deprecated-features).
182
+
183
+
---
184
+
185
+
### Retirement of older Azure AD Connect versions
186
+
187
+
**Type:** Deprecated
188
+
**Service category:** AD Connect
189
+
**Product capability:** User Management
190
+
191
+
Starting August 31 2022, all V1 versions of Azure AD Connect will be retired. If you haven't already done so, you need to update your server to Azure AD Connect V2.0. You need to make sure you're running a recent version of Azure AD Connect to receive an optimal support experience.
192
+
193
+
If you run a retired version of Azure AD Connect it may unexpectedly stop working. You may also not have the latest security fixes, performance improvements, troubleshooting, and diagnostic tools and service enhancements. Also, if you require support we can't provide you with the level of service your organization needs.
194
+
195
+
See [Azure Active Directory Connect V2.0](../hybrid/whatis-azure-ad-connect-v2.md), what has changed in V2.0 and how this change impacts you.
196
+
197
+
---
198
+
199
+
### Retirement of support for installing MIM on Windows Server 2008 R2 or SQL Server 2008 R2
Deploying MIM Sync, Service, Portal or CM on Windows Server 2008 R2, or using SQL Server 2008 R2 as the underlying database, is deprecated as these platforms are no longer in mainstream support. Installing MIM Sync and other components on Windows Server 2016 or later, and with SQL Server 2016 or later, is recommended.
206
+
207
+
Deploying MIM for Privileged Access Management with a Windows Server 2012 R2 domain controller in the PRIV forest is deprecated. Use Windows Server 2016 or later Active Directory, with Windows Server 2016 functional level, for your PRIV forest domain. The Windows Server 2012 R2 functional level is still permitted for a CORP forest's domain. [Learn more](/microsoft-identity-manager/microsoft-identity-manager-2016-supported-platforms).
208
+
209
+
---
210
+
33
211
## July 2021
34
212
35
213
### New Google sign-in integration for Azure AD B2C and B2B self-service sign-up and invited external users will stop working starting July 12, 2021
0 commit comments